Privacy Policy
Last Updated: October 5, 2025
PrepMyCert ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services.
1. Information We Collect
1.1 Personal Information
We collect information that you provide directly to us, including:
- Account Information: Name, email address, password (encrypted)
- Payment Information: Billing details processed securely through Stripe (we do not store credit card numbers)
- Profile Information: Course enrollments, test history, scores, and performance data
- Communication Data: Messages, support tickets, and feedback you send us
1.2 AI Interview Data
When you use our AI Interview Practice feature, we collect:
- Voice Recordings: Audio files of your interview answers (stored securely in Azure Blob Storage)
- Transcripts: Text transcriptions of your spoken answers (generated via Web Speech API or OpenAI Whisper)
- AI Evaluations: Scores, feedback, and analysis generated by AI models
- Performance Metrics: Session data, time taken, question difficulty, and progress tracking
1.3 Automatically Collected Information
- Usage Data: Pages viewed, features used, time spent, click patterns
- Device Information: Browser type, operating system, IP address, device identifiers
- Cookies: Session cookies for authentication and preference tracking
2. How We Use Your Information
We use collected information for the following purposes:
2.1 Service Delivery
- Provide access to practice tests, courses, and AI interview features
- Generate personalized AI feedback and performance analytics
- Track your progress and maintain test history
- Process payments and manage subscriptions
2.2 AI Processing
- Transcribe voice recordings to text using OpenAI Whisper API (fallback only)
- Evaluate answers using OpenAI GPT models to provide constructive feedback
- Generate interview questions tailored to course content
- Improve AI model accuracy and relevance
2.3 Communication
- Send service-related emails (account verification, password resets, purchase confirmations)
- Provide customer support and respond to inquiries
- Send marketing communications (only with your consent; you may opt-out anytime)
2.4 Improvement and Security
- Analyze usage patterns to improve our services
- Detect and prevent fraud, abuse, and security threats
- Comply with legal obligations and enforce our Terms of Service
3. Information Sharing and Disclosure
3.1 Third-Party Service Providers
We share information with trusted third-party providers who assist in operating our services:
- OpenAI: For AI-powered interview evaluation and speech-to-text (subject to OpenAI's privacy policy)
- Microsoft Azure: For cloud hosting, database storage, and file storage
- Stripe: For payment processing (we do not store payment card details)
- Email Service Providers: For transactional and marketing emails
3.2 Legal Requirements
We may disclose your information if required by law or in response to:
- Valid legal process (subpoena, court order, government request)
- Protection of our legal rights or safety of users
- Investigation of fraud or security issues
3.3 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity. We will notify you of any such change.
4. Data Retention
- Account Data: Retained as long as your account is active
- Test Results: Retained for historical tracking and analytics (minimum 2 years)
- Voice Recordings: Retained for 90 days for quality assurance, then deleted
- Transcripts and Evaluations: Retained indefinitely for your learning history
- Payment Records: Retained for 7 years for tax and accounting compliance
5. Your Rights and Choices
5.1 Access and Correction
- View and update your account information in your dashboard
- Request a copy of your personal data by contacting us
5.2 Data Deletion
- Delete your account at any time (some data retained for legal/accounting purposes)
- Request deletion of specific data by contacting us
5.3 Marketing Communications
- Opt-out of marketing emails using the unsubscribe link in any email
- We will still send essential service-related communications
5.4 Cookies
- Manage cookie preferences in your browser settings
- Note: Disabling cookies may limit functionality
6. Data Security
We implement industry-standard security measures to protect your information:
- SSL/TLS encryption for data transmission
- Encrypted password storage using industry-standard hashing
- Secure Azure cloud infrastructure with access controls
- Regular security audits and vulnerability assessments
- Employee training on data protection best practices
However, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.
7. Children's Privacy
Our services are not intended for individuals under 13 years of age. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
8. International Data Transfers
Your information may be transferred to and processed in countries outside your country of residence, including the United States. We ensure appropriate safeguards are in place for such transfers in compliance with applicable data protection laws.
9. California Privacy Rights (CCPA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act:
- Right to know what personal information we collect and how it's used
- Right to delete personal information (subject to certain exceptions)
- Right to opt-out of the sale of personal information (we do not sell your data)
- Right to non-discrimination for exercising your privacy rights
10. European Privacy Rights (GDPR)
If you are in the European Economic Area, you have rights under GDPR including:
- Right of access, rectification, and erasure
- Right to data portability
- Right to object to processing
- Right to lodge a complaint with a supervisory authority
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Posting the new Privacy Policy on this page with an updated "Last Updated" date
- Sending an email notification to your registered email address
Your continued use of our services after changes constitutes acceptance of the updated policy.
12. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy, please contact us:
Email: privacy@prepmycert.com
Address: PrepMyCert Privacy Team, [Your Business Address]
Response Time: We will respond to all privacy inquiries within 30 days